CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,957 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-06
170,204 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2005-1603 EXP | NiteEnterprises Remote File Manager 1.0 allows remote attackers to cause a denial of service (crash) via a crafted string to TCP port 7080. | Patch early | 5.0 medium | 3.1% | 2005-05-16 |
| CVE-1999-0715 EXP | Buffer overflow in Remote Access Service (RAS) client allows an attacker to execute commands or cause a denial of service via a malformed phonebook en… | Patch early | 4.6 medium | 3.1% | 1999-05-20 |
| CVE-2007-5637 EXP | The Nortel UNIStim IP Softphone 2050, IP Phone 1140E, and additional Nortel products from the IP Phone, Business Communications Manager (BCM), and oth… | Patch early | 4.3 medium | 3.1% | 2007-10-23 |
| CVE-2006-0784 EXP | D-Link DWL-G700AP with firmware 2.00 and 2.01 allows remote attackers to cause a denial of service (CAMEO HTTP service crash) via a request composed o… | Patch early | 5.0 medium | 3.1% | 2006-02-19 |
| CVE-2001-0304 EXP | Directory traversal vulnerability in Caucho Resin 1.2.2 allows remote attackers to read arbitrary files via a "\.." (dot dot) in a URL request. | Patch early | 5.0 medium | 3.1% | 2001-05-03 |
| CVE-2007-4327 EXP | Multiple PHP remote file inclusion vulnerabilities in File Uploader 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the config[r… | Patch early | 6.8 medium | 3.1% | 2007-08-14 |
| CVE-2006-6872 EXP | Directory traversal vulnerability in mod.php in eNdonesia 8.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the mod parameter. | Patch early | 5.0 medium | 3.1% | 2006-12-31 |
| CVE-2002-1966 EXP | Directory traversal vulnerability in magiccard.cgi in My Postcards Platinum 5.0 and 6.0 allows remote attackers to read arbitrary files via a .. (dot… | Patch early | 5.0 medium | 3.1% | 2002-12-31 |
| CVE-2005-0479 EXP | Directory traversal vulnerability in ComGetLogFile.php3 for TrackerCam 5.12 and earlier allows remote attackers to read arbitrary files via ".." seque… | Patch early | 5.0 medium | 3.1% | 2005-03-30 |
| CVE-2008-4754 EXP | SQL injection vulnerability in forum.php in Scripts for Sites (SFS) Ez Forum allows remote attackers to execute arbitrary SQL commands via the forum p… | Patch early | 5.8 medium | 3.1% | 2008-10-27 |
| CVE-2006-1147 EXP | The Com_sprintf function in q_shared.c in Alien Arena 2006 Gold Edition 5.00 does not properly NULL terminate certain long strings, which allows remot… | Patch early | 4.0 medium | 3.1% | 2006-03-10 |
| CVE-2008-6785 EXP | Unrestricted file upload vulnerability in Mini File Host 1.5 allows remote attackers to execute arbitrary code by uploading a file with an executable… | Patch early | 6.8 medium | 3.1% | 2009-05-01 |
| CVE-2011-4544 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Prestashop before 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1)… | Patch early | 4.3 medium | 3.1% | 2011-12-01 |
| CVE-2005-3307 EXP | Directory traversal vulnerability in index.php for FlatNuke 2.5.6 allows remote attackers to read arbitrary files via ".." sequences in the (1) user p… | Patch early | 5.0 medium | 3.1% | 2005-10-26 |
| CVE-2004-1221 EXP | Directory traversal vulnerability in weblibs.pl in WebLibs 1.0 allows remote attackers to read arbitrary files via .. sequences in the TextFile parame… | Patch early | 5.0 medium | 3.1% | 2005-01-10 |
| CVE-2011-4871 EXP | Open Automation Software OPC Systems.NET before 5.0 allows remote attackers to cause a denial of service via a malformed .NET RPC packet on TCP port 5… | Patch early | 5.0 medium | 3.1% | 2012-04-18 |
| CVE-2011-4883 EXP | The web server in Certec atvise webMI2ADS (aka webMI) before 2.0.2 does not properly validate values in HTTP requests, which allows remote attackers t… | Patch early | 5.0 medium | 3.1% | 2012-04-13 |
| CVE-2018-0715 EXP | Cross-site scripting vulnerability in QNAP Photo Station versions 5.7.0 and earlier could allow remote attackers to inject Javascript code in the comp… | Patch early | 6.1 medium | 3.1% | 2018-08-27 |
| CVE-2006-5305 EXP | PHP remote file inclusion vulnerability in lat2cyr.php in the lat2cyr 1.0.1 and earlier phpbb module allows remote attackers to execute arbitrary PHP… | Patch early | 5.1 medium | 3.1% | 2006-10-17 |
| CVE-2008-1221 EXP | Absolute path traversal vulnerability in the FTP server in MicroWorld eScan Corporate Edition 9.0.742.98 and eScan Management Console (aka eScan Serve… | Patch early | 5.0 medium | 3.1% | 2008-03-10 |
| CVE-2007-1908 EXP | PHP file inclusion vulnerability in php121db.php in PHP121 Instant Messenger 2.2 allows remote attackers to execute arbitrary PHP code via a UNC share… | Patch early | 6.8 medium | 3.1% | 2007-04-10 |
| CVE-2007-1937 EXP | PHP remote file inclusion vulnerability in smilies.php in Scorp Book 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the config… | Patch early | 6.8 medium | 3.1% | 2007-04-10 |
| CVE-2007-2181 EXP | PHP remote file inclusion vulnerability in admin/login.php in Webinsta FM Manager 0.1.4 and earlier allows remote attackers to execute arbitrary PHP c… | Patch early | 6.8 medium | 3.1% | 2007-04-24 |
| CVE-2018-14059 EXP | Pimcore allows XSS via Users, Assets, Data Objects, Video Thumbnails, Image Thumbnails, Field-Collections, Objectbrick, Classification Store, Document… | Patch early | 5.4 medium | 3.1% | 2018-08-24 |
| CVE-2008-0736 EXP | admin/SA_shipFedExMeter.asp in CandyPress (CP) 4.1.1.26, and possibly other 4.x and 3.x versions, allows remote attackers to obtain the path via a cer… | Patch early | 5.0 medium | 3.1% | 2008-02-13 |
| CVE-2008-4207 EXP | Attachmax Dolphin 2.1.0 and earlier does not properly protect info.php in the main folder, which allows remote attackers to obtain sensitive informati… | Patch early | 5.0 medium | 3.1% | 2008-09-24 |
| CVE-2005-1165 EXP | Yager 5.24 and earlier allows remote attackers to cause a denial of service (application crash) via certain malformed data. | Patch early | 5.0 medium | 3.1% | 2005-05-02 |
| CVE-2005-1899 EXP | Rakkarsoft RakNet network library 2.33 and earlier, when released before 30 May 2005, and as used in multiple products including nFusion Elite Warrior… | Patch early | 5.0 medium | 3.1% | 2005-06-09 |
| CVE-2019-15253 EXP | A vulnerability in the web-based management interface of Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker… | Patch early | 4.8 medium | 3.1% | 2020-02-05 |
| CVE-2007-0638 EXP | show.php in Vlad Alexa Mancini PHPFootball 1.6 allows remote attackers to obtain sensitive information (database contents) via a % (percent) character… | Patch early | 5.0 medium | 3.1% | 2007-01-31 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt